← Back

CVE-2019-15752

nvd nist
Published: Aug 28, 2019Modified: Nov 6, 2025CISA KEV

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run 'docker login' to force the command.

Affected (2)

Products: Docker: Docker · Apache: Geode
1 product
Docker
1 product
Geode
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.1.0.1
Running on/withPlatform Versions
Microsoft
Windows
All versions
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.12.0

Timeline

No history available yet.